Keepnet AI-powered human risk management platform logo
Menu

What is secure behaviour management?

What secure behaviour management (SBM) is, how it differs from security awareness training and HRM, and what CISOs should ask an SBM vendor.

By Ozan Ucar, Founder and CEO of Keepnet

What is secure behaviour management

Secure behaviour management (SBM) is a security programme that changes how employees act on phishing, SMS, calls and deepfakes, and measures that change before and after.

SBM is the name Gartner now uses for the market long known as security awareness training. Some analysts call the same market human risk management. The tools overlap a lot. The goal is what changes. The question is no longer "did everyone finish the course". It is "do employees behave more securely than before, and can we prove it".

The short version

  • SBM replaces scheduled, email-only training with nudges, multi-channel simulations and training that follow what each employee actually does.
  • You measure it by behaviour change, not completion rate.
  • Gartner tells CISOs to put SBM on the roadmap now and to use the next security awareness renewal as the moment to evaluate it.[1]

Why this page exists

In June I published a post called "The name matters. The outcome matters more." It was about Gartner moving the market language from human risk management to secure behaviour management. A lot of CISOs came back to me with the same question. Ok, but what is SBM in practice, and how is it different from what we already run?

This page is my answer. I rebuilt it after Gartner published "Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management" in September 2026. That note is the clearest description of the market so far, and Keepnet is listed in it, so I will also say where we stand.

SBM, HRM, SBCP and SAT: one market, five names

This market renamed itself almost every time the buyer's question changed. The metric changed much slower than the name.

NameWho and whenThe question it answeredWhat it measured
Security awareness and training (SAT)NIST SP 800-50, 2003Do we have a training programme?Completion
Computer-based training and phishing simulation2010sCan we train at scale, and do employees click?Completion, click rate
Security behavior and culture program (SBCP)Gartner, 2022Can we build a culture, not only a course?Culture and behaviour indicators
Human risk management (HRM)Forrester, 2024Can we find and reduce the risk employees carry?Risk scores
Secure behaviour management (SBM)Gartner, 2026Do employees behave more securely, and can we prove it?Behaviour before and after

HRM and SBM describe the same kind of platform. The difference is the frame. HRM looks at the employee as a risk to reduce. SBM looks at the behaviour you want to see. I prefer the second one. You do not win employees over by calling them a risk.

If you want the longer story of the older terms, we keep two pages for them: what is human risk management and what is a security behavior and culture program.

How SBM is different from security awareness training

This is how I explain it to CISOs:

Security awareness trainingSecure behaviour management
Who gets whatThe same course for everyone, on a calendarTraining and simulations picked by what each employee did
When it reaches the employeeOnce a quarter or once a yearRight after the behaviour, as a short nudge
Channels testedMostly emailEmail, voice, SMS, QR, callback, and deepfakes as opt-in
What goes to the boardCompletion and click rateBehaviour before and after

Gartner is blunt about the old model. It calls SAT "antiquated and commoditized" and tells CISOs to treat it as end-of-life.[1] An earlier Gartner note says it in one line: "Pre-scheduled, calendar-based training achieves compliance, but fails to alter employee behavior."[2]

There is one point I want to add. Compliance training is not going away. Regulators still ask for it, DORA and NCSC guidance included. So SBM does not delete your training library. It changes what decides who gets which training, and when. Gartner makes the same point and tells buyers to check that an SBM platform can still deliver the core SAT features.[1]

Why the name matters less than the metric

Most programmes still report participation. Completion rate, email click rate, courses assigned. These numbers tell you the programme ran. They do not tell you the organisation is safer.

The data is clear on this. The human element appeared in 62% of breaches in the 2026 Verizon DBIR.[3] In the same year, 84% of security leaders said training completion is one of their top metrics.[4] Those two numbers do not belong in the same programme.

It gets sharper. 41% of employees admit they bypassed security guidance, and 61% of them knew it raised risk when they did it.[5] Employees are aware. The problem is the decision in the moment, and a completion dashboard cannot see that.

Completion rate is a comforting number. It is not a security outcome.

How do you measure secure behaviour?

Report outcomes, not activity:

Stop leading withStart leading with
Training completion rateReported phishing rate and how fast employees report
Email click rate onlyRisky actions across email, voice, SMS, QR and callback
Courses assignedIncidents prevented and repeat behaviour going down
One score at one point in timeThe same employees, before and after

This is what that looks like on our own data. We looked at employees who received at least 12 email phishing simulations on Keepnet between January 2020 and September 2026.

  • 48% fewer clicks after the first simulation. The first simulated phishing email is the one employees are most likely to click: 9.2%, falling to 4.8% across every simulation that follows. The template difficulty stayed flat between the first and the twelfth, so easier templates do not explain the drop.[6]
  • 58% lower at the median organisation. The median organisation's click rate fell from 3.4% on its employees' first simulation to 1.4% by their twelfth.[6]
  • The drop held in every cohort size tested, between 31% and 50%.[6]

Your own starting rate will depend on how hard your templates are. The drop is the part that carries across. That is the kind of before and after reading SBM asks you to put in front of the board.

What an SBM platform has to do

Gartner lists the capabilities that separate SBM from SAT.[1] Here they are in my words, with what I would check and where Keepnet is today.

CapabilityWhat I would checkKeepnet today
Nudges in the momentDo nudges fire on behaviour, not only on a schedule? Is there a cap?Nudges by email, SMS and Microsoft Teams, behaviour-based or scheduled, with a frequency cap per employee
Automation per employeeIs each employee's training and simulation picked for them?Agentic AI plans and runs campaigns, with approval before anything goes out
Multi-channel simulationsEmail, voice, SMS and video, from the vendor's own numbers?Email, voice, SMS, QR and callback simulations; voice calls are pre-recorded, text-to-speech, or two-way calls held by an AI agent; deepfakes are opt-in
Adaptive by behaviour, role and riskDoes what the employee did change what they get next?Risky and positive behaviours recorded per employee with a severity; reporting rate, completion and repeated risky behaviour decide what comes next
Integrations with security toolsDoes it take signals from your stack?Microsoft Entra ID Protection and Microsoft Defender as signal sources, Teams for nudges
Before and after measurementCan it show the same employees before and after?Behaviour measured before and after, by employee, department and channel

Do not take this table on trust, including ours. Gartner tells buyers to test vendor claims in a live proof of concept before buying.[1] I agree.

AI makes SBM faster. It also makes it easier to get wrong.

AI is the reason this market moved. It is also where most of the risk sits now. Gartner warns that unvetted AI features can trigger employee and executive backlash, and shares cases like an AI agent that sent a simulation spoofing the payroll team and caused panic across a company.[1] That is a career problem for a CISO, not only a technical one.

Gartner's advice is "crawl, walk, run". Pilot new features on IT and security staff first. Keep a person approving before anything runs on its own. Make deepfakes opt-in.[1]

This is how we built Keepnet's Agentic AI:

  • Approval is the default. Autonomous mode only runs inside policies you set.
  • AI-generated simulations are produced inside a global framework plus your own company policy.
  • Deepfakes are opt-in, and you approve who appears in one.
  • Simulations and nudges have a frequency cap, so employees do not get worn out.

Questions I would ask any SBM vendor, including us

These come from Gartner's buyer guidance.[1] I added one of my own at the end.

The business case

  • What is the real price difference between our SAT renewal and your platform?
  • Can you still deliver our compliance training, or do we need to keep another tool?
  • Have we tested it live, or only seen a demo?

AI control

  • Is there human-in-the-loop review before anything runs autonomously?
  • Can we pilot AI features with a small group first?
  • What stops an AI agent from going wrong at scale?

Employee backlash

  • How do you catch errors in AI-generated training?
  • What stops a simulation from breaking our legal or internal policies?
  • What safeguards are there around deepfakes of our own executives?
  • How do you stop nudge fatigue?

And mine

  • Show me the behaviours behind your risk score. Gartner warns that proprietary risk scores are often opaque and biased towards what the platform can see.[1] If a vendor cannot show what moved the score, the score is not a metric.

Multi-channel is not optional

81% of organisations had at least one phishing, vishing or smishing incident in the past year.[1] Almost all of them run security awareness training.

In the 2026 Verizon DBIR, employees act on phone-based simulations about 40% more often than on email.[3] Keepnet contributed simulation data to that comparison. A programme that only tests email is measuring the easiest channel, not the channels attackers use.

What to do on Monday

  1. Put SBM on your roadmap, and treat your next SAT renewal as the moment to evaluate it.[1]
  2. Keep completion rate for compliance, but stop leading with it. Lead with behaviour before and after.
  3. Test beyond email: voice, SMS, QR and callback.
  4. Start small with AI. Pilot on IT and security staff, then widen.

Where Keepnet sits

Keepnet is listed in Table 1, Representative List of Secure Behavior Management Vendors, in Gartner's September 2026 note, one of 25 vendors listed.[1] Keepnet is also listed among the example vendors for dynamic nudging and deepfake-based simulation training in Gartner's "Fight AI Disinformation" playbook.[2]

Keepnet is an AI-native secure behaviour management platform. Every product can be bought on its own: the phishing simulator, security awareness training, Incident Responder and Agentic AI.

See it running · Book a demo

Sources

  1. Gartner, "Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management", William Candrick, Alex Michaels, 22 September 2026 (G00860839). 2026 Gartner CISO Role Survey (n=297).
  2. Gartner, "Fight AI Disinformation: A CISO Playbook for Working with Your CIO, CCO and CMO", Akif Khan, 23 October 2025 (G00840501).
  3. Verizon, 2026 Data Breach Investigations Report, p. 12 and p. 50; contributors list, p. 118.
  4. Gartner, "6 Ways to Transform Your Cybersecurity Awareness Program" (G00840741, March 2026), 2025 Secure Behavior Strategies Survey (n=65).
  5. Gartner (G00840742, February 2026), employee survey (n=175).
  6. Keepnet anonymised customer research, email phishing simulations delivered 1 January 2020 to 29 September 2026. Per employee: employees who received at least 12 simulations (n=102,452 employees across 158 organisations). Per organisation: median of the same 158 organisations. Methodology: doc.keepnetlabs.com/resources/research-methodology.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner's business and technology insights organization and should not be construed as statements of fact. GARTNER is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.

SHARE ON

twitter
linkedin
facebook

Book a demo

You'll learn how to:
tickSee which behaviours create the most risk in your organisation
tickPlan training, nudges and simulations by role and channel
tickMeasure behaviour before and after

Frequently Asked Questions